Product & Version:
InstantForum.NET
v4.1.3 v4.1.1 v4.1.2 v4.0.0 v4.1.0 v3.4.0Vendor URL & Download:
InstantForum.NET can be purchased from here,http://docs.instantasp.co.uk/InstantForum/default.html?page=v413tov414guide.htmlProduct Introduction Overview:
“InstantForum.NET
is a feature rich, ultra high performance ASP.NET & SQL Server
discussion forum solution designed to meet the needs of the most
demanding online communities or internal collaboration environments. Now
in the forth generation, InstantForum.NET has been completely rewritten
from the ground-up over several months to introduce some truly unique
features & performance enhancements.”
“The new administrator control panel now offers the most comprehensive
control panel available for any ASP.NET based forum today. Advanced
security features such as role based permissions and our unique
Permission Sets feature provides unparalleled configurable control over
the content and features that are available to your users within the
forum. Moderators can easily be assigned to specific forums with
dedicated moderator privileges for each forum. Bulk moderation options
ensure even the busiest forums can be managed effectively by your
moderators.”
“The forums template driven skinning architecture offers complete
customization support. Each skin can be customized to support a
completely unique layout or visual appearance. A single central style
sheet controls every aspect of a skins appearance. The use of unique
HTML wrappers and ASP.NET 1.1 master pages ensures page designers can
easily integrate an existing design around the forum. Skins, wrappers
& master page templates can be applied globally to all forums or to
any specific forum.”(2) Vulnerability Details:
InstantForum.NET web
application has a cyber security bug problem. It can be exploited by
stored XSS attacks. This may allow a remote attacker to create a
specially crafted request that would execute arbitrary script code in a
user’s browser session within the trust relationship between their
browser and the server.

Several
other similar products 0-day vulnerabilities have been found by some
other bug hunter researchers before. InstantForum has patched some of
them. BugScan is the first community-based scanner, experienced five
code refactoring. It has redefined the concept of the scanner provides
sources for the latest info-sec news, tools, and advisories. It also
publishs suggestions, advisories, cyber intelligence, attack defense and
solutions details related to important vulnerabilities.

(2.1) The first programming code flaw occurs at “&SessionID” parameter in “Join.aspx?” page.(2.2) The second programming code flaw occurs at “&SessionID” parameter in “Logon.aspx?” page.